Courseiva
Vulnerability Scanning →mediumMultiple Choice

GPEN Vulnerability Scanning Practice Question

A penetration tester is conducting a vulnerability scan against a web application and notices that the scanner reports a critical SQL injection vulnerability on a page that does not accept user input. The tester manually verifies the page and finds no input fields or parameters. What is the most likely cause of this false positive?

⚠ Common exam trap

The trap here is assuming that a page with no input cannot be vulnerable, overlooking that scanners may test HTTP headers or other vectors that are not visible in the UI.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The scanner is configured to perform blind SQL injection tests by injecting payloads into HTTP headers.

The most likely cause is that the scanner injects payloads into HTTP headers, which the application may log into a database. If the logging is vulnerable, the scanner could detect SQL injection even though the page itself has no input. This is a common source of false positives in web application scanning. Other options do not explain why a false positive would occur on a page with no user input.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The scanner is using an outdated vulnerability database.

    Why it's wrong here

    An outdated database could miss new vulnerabilities or misclassify known ones, but it would not typically cause a false positive on a page with no input. False positives from outdated signatures are more likely when the signature is too broad, but the absence of input makes this unlikely. The issue is more about how the scanner interacts with the page.

  • ✓

    The scanner is configured to perform blind SQL injection tests by injecting payloads into HTTP headers.

    Why this is correct

    Some scanners test for SQL injection by injecting payloads into HTTP headers such as User-Agent or Referer, even if the page has no user input. If the application logs these headers into a database without proper sanitization, the scanner might detect a vulnerability. This can cause a false positive if the page itself is not vulnerable but the logging mechanism is, or if the scanner misinterprets the response.

  • ✗

    The scanner is using a safe checks policy that skips destructive tests.

    Why it's wrong here

    A safe checks policy reduces the risk of denial-of-service but does not cause false positives. It may skip some tests, but it would not report a vulnerability on a page with no input. The presence of a false positive indicates an over-reporting issue, not a safety setting.

  • ✗

    The scanner is unable to authenticate to the web application.

    Why it's wrong here

    Lack of authentication might lead to incomplete coverage or false negatives, but it would not create a false positive on a page that is accessible. The scanner might miss authenticated areas, but the reported vulnerability is on a page that does not accept input, so authentication status is irrelevant to the false positive.

About these practice questions

One of 298 original GPEN practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GPEN practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GPEN exam.